Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Windows passkey relay mitigation for CVE-2026-34348

Advisory/Mitigation
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication abuse on Windows systems. Microsoft said it has applied mitigations and that defenders should install the applicable security updates. The guidance also calls for least-privilege access, phishing-resistant authentication, and stronger endpoint protections. The advisory ties the response to a vendor CVSS 6.5 issue and a broader hardening push across authentication methods.

Related Happenings

Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)

Vulnerability
H score49 First: 21.08.2026 09:06 Last: 21.08.2026 09:06 Sources 1

About this happening: Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...

Pass-ta-key attacks against Google Password Manager on Windows TPM devices

Technical Analysis
H score23 First: 04.08.2026 02:58 Last: 04.08.2026 02:58 Sources 1

How related: Unit 42's Pass-ta-key research targets Google Password Manager's synced-passkey system in Chrome on Windows.

About this happening: Pass-ta-key is a technical analysis of three attacks against Google Password Manager synced passkeys in Chrome on Windows devices with TPM. Palo Alto Networks Un...

Chrome Google Password Manager passkey post-compromise techniques on Windows

Technical Analysis
H score3 First: 03.08.2026 19:24 Last: 03.08.2026 19:24 Sources 1

How related: Unit 42 showed attacks against Google Password Manager in Chrome, including a path that recovers the private keys for a victim's synced passkeys.

About this happening: Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...

Microsoft AD CS Certighost improper authorization flaw (CVE-2026-54121)

Vulnerability
H score37 First: 24.07.2026 17:15 Last: 24.07.2026 17:15 Sources 1

About this happening: CVE-2026-54121 (Certighost) is a Microsoft Active Directory Certificate Services (AD CS) vulnerability that can let an authenticated attacker obtain a certificate for...

Microsoft AD CS security update for CVE-2026-54121

Security Patch Release
H score34 First: 24.07.2026 17:15 Last: 24.07.2026 17:15 Sources 1

About this happening: Certighost (CVE-2026-54121) is a Microsoft Active Directory Certificate Services (AD CS) vulnerability that lets a low-privileged Active Directory user abuse chase f...

Timeline

  1. 10.08.2026 15:25 2 articles · 13d ago

    Microsoft applies mitigations for passkey relay assertions and CVE-2026-34348

    Mitigation Patch Update

    Microsoft said it applied mitigations for a reported passkey relay assertions issue and advised Windows defenders to install the applicable security updates for CVE-2026-34348, an information-disclosure vulnerability in the Windows Event Logging Service affecting Windows 10, Windows 11 and Windows Server. The vendor also recommended least-privilege access, phishing-resistant authentication methods, endpoint protections and a Zero Trust security model.

    Show sources